Claude Code MCP sign-in link stopped working: use the newest one
A repeat MCP sign-in request replaces the pending link in Claude Code, so the older link can stop working. Finish the newest Sume sign-in link only.

If a Sume sign-in link from Claude Code does nothing, request sign-in once more and open only the newest link. The Claude Code changelog lists a fix where a repeat MCP sign-in request replaced the pending link, "which could stop that link from working".
The changelog line is the only vendor claim used here. The Sume flow is from MCP OAuth and API keys. Both were read 2026-10-01.
What does the changelog say?
One entry reads: "Fixed a repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working". It does not say which versions are affected beyond where it appears in the changelog, so check the entry against the version you run.
What does the Sume sign-in look like?
The docs describe six steps. Step 3 is the one that produces a link: the client sends the user to https://mcp.sume.com/oauth/authorize, which redirects to the consent page on the MCP host. Each new sign-in request starts that sequence again.
| Step | What happens |
|---|---|
| 1 | Client connects to https://mcp.sume.com/mcp. |
| 2 | Sume returns an OAuth challenge and protected-resource metadata. |
| 3 | Client sends the user to /oauth/authorize on the MCP host. |
| 4 | Consent: Read locked on, Write off by default. |
| 5 | Client exchanges the authorization code (PKCE) for an access token. |
| 6 | Client calls the endpoint with that bearer token. |
Why would an older link fail?
Because step 5 is a PKCE exchange, the code that comes back has to be completed by the client that started that request. If the client replaced its pending request, a link from the earlier attempt has no client waiting for it. That is an inference from the PKCE step and the changelog entry, not something either page states. Sume advertises S256 as the supported challenge method.
What should I do when the link fails?
Close the old browser tab, ask Claude Code to sign in once, and finish that one link without requesting another meanwhile. Access tokens last one hour, so you may repeat this later; see the one-hour token note. Over SSH with no browser, use the SSH login guide.
Sources
Related posts
More in Integrations
- Codex default_tools_approval_mode writes with Sume tools
With default_tools_approval_mode = "writes", Codex prompts for tools not marked read-only. Sume marks reads readOnlyHint true and writes false.
- Claude highlight edit from a long video: Resolve 21.1 vs Sume MCP
Resolve 21.1 lets Claude edit highlights inside Resolve. Sume's hosted MCP can do a cloud version: inspect, trim ranges, join with timeline_create.
- Devin Desktop MCP authorization opens the provider: Sume page
Devin Desktop 3.10.23 opens MCP authorization at the provider directly. For Sume that is mcp.sume.com/oauth/authorize, then a consent page on the MCP host.
- Devin MCP write scopes by default: Sume keeps write opt-in
Devin now requests read/write scopes by default for Microsoft 365 MCP. Sume's hosted MCP asks for read only unless the user turns Write on at consent.
Written by Sume